tomchop · @tomchop
707 followers · 94 posts · Server infosec.exchange

"But plaso/logt2imeline are hard to install! 😭", I hear you cry.

Here's how to set up aliases and get it running in under 2 seconds using the official Docker containers 👇🏻 # DFIR

#plaso #log2timeline #docker #forensics

Last updated 2 years ago

Wes Lambert · @weslambert
358 followers · 45 posts · Server infosec.exchange

🦖Day 83 of the @velocidex series

Artifact: Server.Utils.BackupGCS/S3

Link:
docs.velociraptor.app/artifact

docs.velociraptor.app/artifact

----

These artifacts are server monitoring artifacts that will watch for flow completions, then zip and send the results to Google Cloud, or an S3 bucket, using the 'upload_gcs()' and 'upload_s3()' functions.

docs.velociraptor.app/vql_refe

docs.velociraptor.app/vql_refe

----

Once uploaded, the collections can be left alone and remain archived, or special post-processing can be applied using third-party tools, depending on defenders' needs.

@eric_capuano and @shortxstack (@recon_infosec) did an excellent job presenting about using these artifacts with Timesketch to generate a timeline of events.

If you haven't already, be sure to check out their presentation from @SANS Summit 2021!

sans.org/presentations/breache

----

That's it for now! Stay tuned to learn about more artifacts! 🦖






#velociraptor #artifactsofautumn #dfir #forensics #infosec #plaso #threathunting #Timesketch

Last updated 2 years ago